Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

When restoring the default configuration, the script will also update StudioService.exe.config to set the correct authority url for the newly created realm and the new client secret for the studio-server client.

User Federation: NTLM/LDAP

Note

You may need to consult your administrator in order to fill in the following fields.

It is possible to link Keycloak to an Active Directory using User Federation. This will allow users to sign in using their AD credentials. To set this up:

  1. Select User Federation from the navigation panel. From the Add provider drop-down, select ldap.
    Image Added

  2. Select which vendor is used:
    Image Added


  3. Enter the connection url, including the ldap:// prefix. The following command line command may assist in determining the correct url: nslookup -type=all _ldap._tcp.Image Added


  4. Select which credentials Keycloak will use to query the AD, for example as CN=Keycloak,CN=Services,DC=company,DC=com.
    Image Added
  5. Test authentication to ensure the configuration works.
  6. As Edit Mode, choose READ_ONLY
    Image Added
  7. Select where in the LDAP tree Keycloak can find the Studio users that should be able to log in, for example CN=MyStudioUsers,DC=company,DC=com.Image Added
  8. Save your changes
  9. Sync all users in the top right corner:
    Image Added

User Federation: Kerberos

It is possible to link Keycloak to an Active Directory with the Kerberos protocol using User Federation. This will allow users to sign in using their AD credentials. To set this up:

  1. Select User Federation from the navigation panel and then select "Add Kerberos providers".
    Image Added
  2. Choose a UI display name
  3. Enter the Kerberos Realm
    Image Added
  4. Enter the principal for the server 
    Image Added
  5. Enter the location of the keytab file containing credentials of the given principal
    Image Added
  6. Set Allow Password Authentication to On:
    Image Added
  7. Set Edit Mode to READ_ONLY
    Image Added
  8. In order to test it, a AD user can try to sign in to the Account console for the Studio realm at http://<domain:port>/Keycloak/realms/<realm>/account